CVE-2022-47986
17.02.2023, 16:15
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | aspera_faspex | 𝑥 ≤ 4.4.1 |
ibm | aspera_faspex | 4.4.2 |
ibm | aspera_faspex | 4.4.2:patch_level_1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References